๐Ÿ” CVE Alert

CVE-2026-54334

CRITICAL 9.8

UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen`

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT = 9 and can obtain 511 entries for the 510-element Sd->mCLen heap array because its loop does not enforce Index < NC. The CharC == 2 run-length path can additionally request up to 531 zero writes through Sd->mCLen[Index++] = 0. The normal CompressedSection.process() to efi_compressor.TianoDecompress() to TianoDecompress() to DecodeC() to ReadCLen() parsing path therefore permits crafted Tiano or EFI compressed firmware to corrupt heap memory, deterministically crash the parsing process, and potentially execute code depending on build and runtime details. This issue is fixed in version 1.14.

CWE CWE-787
Vendor theopolis
Product uefi-firmware-parser
Published Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for theopolis uefi-firmware-parser

Be the first to know when new critical vulnerabilities affecting theopolis uefi-firmware-parser are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

theopolis / uefi-firmware-parser
< 1.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/theopolis/uefi-firmware-parser/security/advisories/GHSA-hm2w-vr2p-hq7w github.com: https://github.com/theopolis/uefi-firmware-parser/pull/145 github.com: https://github.com/theopolis/uefi-firmware-parser/commit/bf3dfaa8a05675bae6ea0cbfa082ddcebfcde23e github.com: https://github.com/theopolis/uefi-firmware-parser/releases/tag/v1.14